The Cyber Security Agency of Singapore (CSA) has published an in-depth analysis of the Anonymous hacktivist collective's resurgence during the Russia-Ukraine conflict, examining two decades of the group's evolution from internet pranksters to one of the most prominent hacktivist operations in the world.
Declaring Cyber War on Russia
Following Russia's large-scale invasion of Ukraine on February 24, 2022, Anonymous declared cyber war against Russia. The collective claimed credit for infiltrating the Russian Ministry of Defence database, launching DDoS attacks against Russian government websites, and hacking multiple state TV channels to broadcast pro-Ukraine content. The CSA assessed Anonymous as one of the more technically skilled and dangerous hacker groups to join the conflict.
However, the bulletin noted that Checkpoint Security had observed many claimed hacks by various groups in the conflict were either false or insignificant, with groups appearing more focused on building reputation than causing real damage.
Two Decades of Evolution
The CSA traced Anonymous's trajectory from its origins on the 4chan imageboard in 2003 through key campaigns:
- 2008, Project Chanology — DDoS attacks and physical protests against the Church of Scientology over perceived internet censorship
- 2010, Operation Payback — Attacks on PayPal, MasterCard, and Visa after payment freezes on WikiLeaks donations
- 2013, #OpIsrael — Annual defacement and DDoS campaigns targeting Israeli internet infrastructure
- 2015, #OpISIS — Doxing ISIS members and DDoS attacks on Islamic State websites following the Paris attacks
- 2020, BlueLeaks — Leak of 269 GB of internal police files from over 200 U.S. agencies, exposing personal data of 700,000 officers during the George Floyd protests
Unpredictable and Collateral
The CSA cautioned that while Anonymous's declared motives may appear noble, the collective is fundamentally unpredictable due to its decentralized structure and members' wildly differing ideologies. The bulletin highlighted that ordinary people bear significant collateral damage — PayPal service disruptions inconvenienced millions of users, and BlueLeaks exposed innocent officers' personal data.
Organizations were advised to strengthen cybersecurity posture during geopolitical tensions, patch website vulnerabilities diligently, and deploy DDoS mitigation tools to prevent becoming collateral damage in hacktivist campaigns.